T&T | Cyber: CST | Deputy Manager | ISO:27001 | Coimbatore

Deloitte

Fresher Coimbatore Full Time Work from office
Deloitte logo
Posted : yesterday
Actively hiring

Job description

Join our dedicated cybersecurity team and play a pivotal role in strengthening enterprise security. This position focuses on managing the complete lifecycle of security findings, ensuring robust protection for critical assets.

We are looking for an experienced Cyber Security Subject Matter Expert (SME) to enhance our Security Findings Lifecycle Management program for a major client. You will provide essential technical expertise, validating remediation plans, assessing alternative controls, reviewing exceptions, and verifying closure evidence.

Your role will involve acting as the primary technical advisor for findings related to Application Security, Cloud Security, Network Security, and Infrastructure Security. You'll ensure identified risks are effectively managed and closed according to stringent security standards.

Responsibilities

Oversee the entire lifecycle of security findings from identification through closure, acting as the dedicated technical SME.

Review and validate findings from various sources, including vulnerability assessments, security reviews, audits, cloud security assessments, and compliance checks.

Assess the risk and technical implications of identified security findings.

Collaborate closely with application, infrastructure, cloud, and network teams to drive effective remediation activities.

Ensure findings are accurately categorized, prioritized, tracked, and resolved within defined service level agreement (SLA) timelines.

Provide expert technical guidance to stakeholders on remediation strategies and risk reduction methodologies.

Support governance processes essential for managing and closing security findings.

Conduct risk assessments for security policy, standard, and control exceptions across diverse environments.

Evaluate business justifications, technical exposures, threat likelihoods, and potential impacts associated with exception requests.

Identify and assess compensating controls to mitigate residual risk when standard security requirements cannot be met.

Document risk ratings, provide actionable recommendations, and outline approval requirements for exception requests.

Facilitate review and approval workflows involving security leadership, risk owners, and business stakeholders.

Track the validity, expiration dates, renewal requirements, and associated remediation plans for exceptions.

Monitor and report on exception-related risk exposure, emerging trends, and aging metrics.

Ensure risk acceptance decisions are properly documented and approved in line with organizational governance.

Challenge exception requests with viable remediation options and propose alternative security controls.

Support periodic reviews of approved exceptions to assess ongoing business needs and evolving risk postures.

Review remediation plans proposed by application, cloud, and infrastructure teams, validating their effectiveness against the root cause of security findings.

Recommend alternative remediation approaches when proposed solutions are insufficient for risk mitigation.

Ensure remediation recommendations align with organizational security standards and industry best practices.

Evaluate security architecture changes introduced during remediation activities.

Provide technical consultation for complex or high-risk security findings.

Support and contribute to system administration and maintenance procedures to maintain validated states with adequate controls.

Serve as a key quality contact and primary Subject Matter Expert (SME) for Computer System Validation (CSV) and Quality Risk Management.

Qualifications

We are seeking an experienced professional with a strong background in cybersecurity and a proven ability to manage security findings throughout their lifecycle.

Key responsibilities include reviewing and validating security findings, assessing risks, and collaborating with cross-functional teams to drive remediation.

You should be adept at performing risk assessments, evaluating exceptions, and recommending compensating controls.

Exceptional communication and collaboration skills are essential for working effectively with stakeholders at all levels.

Knowledge of ISO 27001 standards is highly desirable.

Educational Qualification: Any Graduate BE / B.Tech (Tier 1 / Tier 2) in CS / IT / EC / E, OR MCA from a recognized university.

Essential Skills

Security Findings Lifecycle ManagementVulnerability AssessmentSecurity AuditsCloud SecurityCompliance AssessmentsRisk AssessmentApplication SecurityInfrastructure SecurityNetwork SecurityRemediationCybersecurityISO 27001Computer System Validation (CSV)Quality Risk Management

Good to Have

Deloitte

Highlights

  • Actively hiring

More Details

RoleT&T | Cyber: CST | Deputy Manager | ISO:27001 | Coimbatore
IndustryInformation Technology & Services, Cybersecurity
DepartmentInformation Security
Employment TypeFull Time, Work from office

About the Company

Deloitte logo

Deloitte

Information Technology & Services

T&T | Cyber: CST | Deputy Manager | ISO:27001 | Coimbatore at Deloitte | SkillMX | SkillMX